Paper 2026/1943
Finite-Precision Error Analysis of Cryptanalytic Model Extraction
Abstract
Cryptanalytic model extraction treats the parameters of a neural network as hidden secrets and attempts to recover them from black-box oracle access. Existing attacks have shown that such recovery is possible for several neural-network architectures, but practical evaluations typically assume high-precision target-model evaluation, often in float64. This assumption creates a mismatch with deployed machine-learning systems, where models are commonly evaluated in float32 or lower-precision formats. We study cryptanalytic signature recovery under finite-precision target-model evaluation. We decompose the recovery pipeline into numerical subproblems, including critical-point localization, finite-difference estimation and perturbed linear-system solving, and analyze how errors are introduced, propagated, and amplified across these stages. We further relate the resulting perturbation amplification to intrinsic properties of the target network, including the geometry of local linear regions and local parameter-to-gradient sensitivity. In particular, we derive approximate instability boundaries for key precision-sensitive stages of the recovery pipeline. When the target model is evaluated in float32, oracle-induced perturbations cannot be removed by higher-precision downstream computation, leading to a substantially higher local error floor than in the float64 setting. Experimental results suggest that recovery becomes less stable as the network size increases. We also discuss how the finite-precision perspective extends to hard-label recovery and piecewise-affine network components, while smooth non-piecewise-linear activations require additional curvature-aware error modeling.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- A major revision of an IACR publication in ASIACRYPT 2026
- Keywords
- Cryptanalytic Model ExtractionFinite-Precision AnalysisSignature RecoveryNumerical StabilityReLU Neural Networks
- Contact author(s)
-
xuduo @ stu xidian edu cn
liuzhang academic @ gmail com
zlwang @ xidian edu cn - History
- 2026-09-14: revised
- 2026-09-09: received
- See all versions
- Short URL
- https://ia.cr/2026/1943
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1943,
author = {Duo Xu and Liu Zhang and Zilong Wang},
title = {Finite-Precision Error Analysis of Cryptanalytic Model Extraction},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1943},
year = {2026},
url = {https://eprint.iacr.org/2026/1943}
}